Lightweight group switching authentication method and system
A lightweight group handover authentication method that initializes keys using the 5G-AKA protocol, performs AMF registration verification, message relay, and pre-aggregation verification solves the problems of high handover latency and weak security in 5G ultra-dense networks, achieving low-latency and high-security group handover authentication.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING UNIV OF POSTS & TELECOMM
- Filing Date
- 2025-12-19
- Publication Date
- 2026-05-01
AI Technical Summary
Existing 5G handover protocols have security vulnerabilities in ultra-dense networks, leading to desynchronization attacks and failure of forward key confidentiality. Group authentication has high latency and is susceptible to DoS attacks, making it unsuitable for the high-frequency handover requirements of large-scale devices.
A lightweight group handover authentication method is adopted, which initializes the key through the 5G-AKA protocol, performs AMF registration verification, message relay mechanism and pre-aggregation verification, and uses shared key to filter invalid responses to establish secure communication.
It reduces handover latency, enhances resistance to DoS attacks, ensures forward key confidentiality, adapts to dynamic group management, reduces core network signaling and computational overhead, and is suitable for complex network environments.
Smart Images

Figure CN121968098A_ABST
Abstract
Description
A lightweight group handover authentication method and system Technical Field
[0001] This invention belongs to the field of 5G network technology, specifically relating to a lightweight group handover authentication method and system. Background Technology
[0002] As 5G networks evolve towards ultra-dense networks (UDN), scenarios such as enhanced mobile broadband (eMBB) and massive machine-type communications (mMTC) drive the access of massive numbers of devices, significantly increasing the frequency of user equipment (UE) handover between base stations. While 5G networks support heterogeneous access modes, which improves network flexibility, it also requires handover authentication protocols to adapt to the security needs of diverse devices, significantly increasing design complexity.
[0003] In existing 5G handover protocols, the Xn interface-based scheme has significant security vulnerabilities. When the source base station (S-gNB) is infected, it is susceptible to desynchronization attacks and failure of forward key confidentiality. To address the surge in core network signaling and computational overhead caused by simultaneous handover of numerous devices, existing technologies employ group authentication schemes, where a group leader (GL) aggregates member responses to alleviate network burden. However, these schemes still have drawbacks: firstly, high communication latency, requiring the GL to enter the target base station's (T-gNB) coverage area before authentication can begin, preventing early-arriving members from communicating in a timely manner; secondly, weak resistance to DoS attacks, where a single invalid response can cause the entire group authentication to fail. Summary of the Invention
[0004] In view of this, the purpose of this invention is to provide a lightweight group handover authentication method and system to solve or partially solve the problems mentioned in the background art.
[0005] Based on the above objectives, in a first aspect, the present invention provides a lightweight group handover authentication method, comprising: an initialization phase in which each User Equipment (UE) and the 5G core network (5GC) complete authentication and negotiate a session key via the 5G-AKA protocol; the UE and the AMF respectively derive a root key, NextHop parameters, and the session key based on the session key; the AMF securely distributes the session key to the source base station (S-gNB); and the UE and the S-gNB establish communication based on the session key; and a registration phase in which, based on the key foundation of the initialization phase, UEs to be joined to the group sequentially complete AMF registration and group leader (GL) registration, wherein the AMF registration confirms the UE through bidirectional MAC verification. In conjunction with the AMF's identity verification, the AMF generates an identity authentication token for the UE. The GL registration completes identity verification using the token submitted by the UE, and the UE and GL negotiate to generate a shared key. During the handover authentication phase, the GL initiates a handover request based on the group association relationship established during the registration phase. The AMF coordinates with the target base station T-gNB to derive the key and response information required for handover using the key parameters derived during the initialization phase. A signaling channel between the GL and T-gNB is constructed through a message relay mechanism. Pre-aggregation verification is performed using the shared key negotiated during the registration phase, filtering invalid responses and aggregating valid responses to complete the final authentication between the UE and T-gNB and establish secure communication after handover.
[0006] As a preferred solution for lightweight group handover authentication, the specific implementation of the initialization phase includes: each UE and 5GC authenticate with each other through the 5G-AKA protocol and negotiate an initial session key; the UE and AMF respectively derive a root key, key derivation intermediate parameters, and a base station communication key based on the initial session key through a key derivation algorithm. The root key is used for UE and AMF authentication and key derivation, the key derivation intermediate parameters provide the basis for subsequent key generation, and the base station communication key is used for communication between the UE and S-gNB; the AMF securely distributes the base station communication key to the S-gNB, and the UE and S-gNB establish encrypted communication based on the base station communication key.
[0007] As a preferred solution for lightweight group handover authentication, the specific steps of AMF registration are as follows: The UE generates a random challenge value, calculates a verification value using its own root key through a message authentication code algorithm, and then sends the verification information to the AMF; the AMF calculates the verification value using the same parameters, generates a random challenge value after comparison, calculates the response verification value, and feeds it back to the UE; after the UE verifies the validity of the response verification value, it calculates the challenge response value and sends it to the AMF; after the AMF verifies the UE's identity, it confirms the UE's legitimacy; the AMF derives an identity authentication credential based on the key parameters of GL, and the identity authentication credential serves as the UE's identity basis during the GL registration stage. The credential is encrypted using an encryption algorithm, and an integrity verification value is calculated; the UE decrypts the identity authentication credential, verifies the integrity verification value, and stores the credential.
[0008] As a preferred solution for lightweight group handover authentication, the specific steps of GL registration are as follows: The UE generates a random challenge value, calculates a verification value using the stored identity authentication credentials and its own identity identifier, and sends the challenge value, identity identifier, and verification value to the GL; The GL derives identity authentication credentials based on its own key parameters, calculates the verification value, and confirms the UE's identity is valid after comparison, and generates a response value; The UE calculates the expected response value and compares it with the received response value, and if they match, the registration is successful. The UE and the GL negotiate and generate a shared key through a key derivation algorithm for response verification during the handover authentication phase.
[0009] As a preferred solution for lightweight group handover authentication, the message relay mechanism is implemented as follows: The UE that first enters the T-gNB coverage area in the group acts as a relay device. It derives the latest key intermediate parameters based on its own key parameters, calculates the verification value corresponding to the identity identifier, and sends it to the T-gNB. The T-gNB queries the corresponding key intermediate parameters through the identity identifier, verifies the validity of the verification value, and sends the response information of all UEs in the group, the aggregated verification value, and the session identifier to the relay UE. The relay UE uses the session identifier and the latest key intermediate parameters to derive its own new communication key. After verifying the validity of its own response information, it forwards all signaling to the GL. Subsequent handover authentication signaling between the GL and the T-gNB is bidirectionally forwarded through this relay UE until the GL enters the T-gNB coverage area.
[0010] As a preferred solution for lightweight group handover authentication, the pre-aggregation verification mechanism is implemented as follows: During the handover authentication phase, after each UE completes T-gNB identity authentication, it generates an acknowledgment response, calculates a verification value using the shared key negotiated with the GL during the registration phase, the acknowledgment response, and the session identifier, and sends the acknowledgment response and verification value to the GL; For each UE, the GL calculates the expected verification value using the corresponding shared key, acknowledgment response, and session identifier; If the expected verification value matches the received verification value, the acknowledgment response is confirmed as a valid response; If they do not match, the invalid response is discarded and not included in the aggregation process; The GL aggregates all valid acknowledgment responses through XOR operation, generates an aggregated response, and forwards it to the T-gNB, completing the group response aggregation.
[0011] Secondly, the present invention provides a lightweight group handover authentication system, comprising: an initialization unit, used for each user equipment (UE) to complete authentication and negotiate a session key with the 5G core network (5GC) via the 5G-AKA protocol; the UE and the AMF respectively derive a root key, NextHop parameters, and a session key based on the session key; the AMF securely distributes the session key to the source base station (S-gNB); and the UE and S-gNB establish communication based on the session key; and a registration unit, used for UEs to be joined to the group to sequentially complete AMF registration and group leader (GL) registration based on the key foundation of the initialization unit; the AMF registration confirms the UE and AMF through bidirectional MAC verification. For F, identity legitimacy is verified. The AMF generates an identity authentication token for the UE. The GL registration completes identity verification through the token submitted by the UE, and the UE and GL negotiate to generate a shared key. The handover authentication unit is used by the GL to initiate a handover request based on the group association relationship of the registration unit. The AMF coordinates the target base station T-gNB to derive the key and response information required for handover using the key parameters derived by the initialization unit. A signaling channel between the GL and T-gNB is constructed through a message relay mechanism. Pre-aggregation verification is performed with the shared key negotiated by the registration unit. After filtering invalid responses, valid responses are aggregated to complete the final authentication between the UE and T-gNB and establish secure communication after handover.
[0012] As a preferred solution for a lightweight group handover authentication system, the initialization unit includes: an authentication and initial session key negotiation module, used for each UE to authenticate with the 5GC via the 5G-AKA protocol and negotiate an initial session key; a multi-dimensional key derivation module, used for the UE and AMF to derive a root key, key derivation intermediate parameters, and a base station communication key based on the initial session key through a key derivation algorithm, whereby the root key is used for UE and AMF authentication and key derivation, the key derivation intermediate parameters provide the basis for subsequent key generation, and the base station communication key is used for communication between the UE and the S-gNB; a base station communication key secure distribution module, used by the AMF to securely distribute the base station communication key to the S-gNB; and a UE and S-gNB encrypted communication establishment module, used by the UE and S-gNB to establish encrypted communication based on the base station communication key.
[0013] As a preferred solution for a lightweight group handover authentication system, the registration unit includes: a UE authentication request generation module, used by the UE to generate a random challenge value, calculate a verification value using its own root key through a message authentication code algorithm, and then send the verification information to the AMF; an AMF two-way challenge and verification module, used by the AMF to calculate the verification value using the same parameters, generate a random challenge value after comparison, calculate the response verification value and feed it back to the UE; after the UE verifies the validity of the response verification value, it calculates the challenge response value and sends it to the AMF, and the AMF confirms the UE's legitimate identity after verification; and an identity authentication credential derivation and encryption module, used by the AMF to derive identity authentication credentials based on the GL key parameters, the identity authentication credentials serving as the UE's identity basis during the GL registration phase, and encrypting the credentials using an encryption algorithm. The system comprises the following modules: UE authentication and integrity verification; UE credential decryption and storage module, used by the UE to decrypt the identity authentication credential, verify the integrity verification value, and store the credential; UE group access request generation module, used by the UE to generate a random challenge value, calculate the verification value using the stored identity authentication credential and its own identity identifier, and send the challenge value, identity identifier, and verification value to the GL; GL identity verification and response module, used by the GL to derive the identity authentication credential based on its own key parameters, calculate the verification value, and confirm the validity of the UE's identity after comparison, and generate a response value; and shared key negotiation generation module, used by the UE to calculate the expected response value and compare it with the received response value, if they match, registration is successful. The UE and GL negotiate and generate a shared key through a key derivation algorithm, which is used for response verification during the switching authentication phase.
[0014] As a preferred solution for a lightweight group handover authentication system, the handover authentication unit includes: a relay UE identity authentication and key update module, used by the UE that first enters the T-gNB coverage area in the group as a relay device, deriving the latest key intermediate parameters based on its own key parameters, calculating the verification value corresponding to the identity identifier, and sending it to the T-gNB; a T-gNB relay authorization and signaling delivery module, used by the T-gNB to query the corresponding key intermediate parameters through the identity identifier, verify the validity of the verification value, and send the response information, aggregated verification value, and session identifier of all UEs in the group to the relay UE; and a relay UE signaling verification and forwarding module, used by the relay UE to derive its own new communication key using the session identifier and the latest key intermediate parameters, verify the validity of its own response information, and forward all signaling to the T-gNB. The GL (User Response Group) module generates a UE confirmation response and verification value. During the authentication phase, each UE generates a confirmation response after completing T-gNB authentication. It calculates the verification value using the shared key negotiated with GL during registration, the confirmation response, and the session identifier, and sends the confirmation response and verification value to GL. The GL single-UE response verification and filtering module calculates the expected verification value for each UE using the corresponding shared key, confirmation response, and session identifier. If the expected verification value matches the received verification value, the confirmation response is confirmed as valid; otherwise, the invalid response is discarded and not included in the aggregation process. The GL valid response aggregation and submission module aggregates all valid confirmation responses using an XOR operation, generates an aggregated response, and forwards it to the T-gNB, completing the group response aggregation.
[0015] Thirdly, the present invention provides an electronic device including a processor, a memory, and a program or instructions stored in the memory and executable on the processor, wherein the processor, when executing the program or instructions, implements a lightweight group handover authentication method of the first aspect / second aspect or any possible implementation thereof.
[0016] Fourthly, the present invention provides a computer-readable storage medium storing a program or instructions that, when executed by a processor, implement the steps of the lightweight group handover authentication method of the first aspect / second aspect or any possible implementation thereof.
[0017] The beneficial effects of the present invention can be summarized as follows: First, the present invention uses a message relay mechanism to allow the device that first enters the coverage area of the target base station (T-gNB) in the group to act as a signaling relay. The authentication process can be started without waiting for the group leader (GL) to enter the T-gNB coverage area, thus avoiding the problem that early arrival members cannot communicate due to waiting for the GL, and significantly shortening the overall handover delay.
[0018] Second, a pre-aggregation verification mechanism is adopted. Before aggregating responses, GL verifies the authenticity of each member's response one by one using the shared key negotiated during the registration phase, filtering out malicious or invalid responses, effectively resisting DoS attacks, avoiding the failure of the entire group authentication due to a single invalid response, and improving the robustness of the protocol.
[0019] Third, the AMF uniformly allocates the interaction parameters between the UE and the T-gNB to avoid desynchronization attacks caused by the infection of the source base station (S-gNB); the communication key is derived through the vertical derivation key algorithm to ensure forward confidentiality of the key. Even if the S-gNB leaks the key, the attacker will not be able to deduce the new communication key between the UE and the T-gNB.
[0020] Fourth, through the two-stage registration protocol of AMF and GL, it supports UEs to freely join or leave groups, adapting to the needs of dynamic group management; it does not rely on trusted relay hardware, trajectory prediction or specific scenario constraints, and is suitable for general 5G and ultra-dense network (UDN) environments where GL or relay nodes are untrusted and device movement trajectories are not fixed.
[0021] Fifth, continuing the aggregation advantages of group authentication, GL will effectively aggregate responses into a single message for forwarding through XOR operations, reducing the signaling transmission and computing overhead of the core network and ensuring the response efficiency of the core network to other normal UEs.
[0022] Sixth, without relying on the ideal assumptions of GL or base station security, and using AMF as the core trust anchor, even in the extreme case of gNB leaking communication keys, it can still guarantee the consistency, confidentiality and forward confidentiality of communication keys among UE, gNB and AMF, adapting to complex real-world network environments. Attached Figure Description
[0023] To more clearly illustrate the technical solutions in this invention or related technologies, the drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the drawings described below are only embodiments of this invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0024] Figure 1 is a flowchart of the lightweight group handover authentication method provided in an embodiment of the present invention; Figure 2 is a flowchart of the AMF registration stage in the lightweight group handover authentication method provided in an embodiment of the present invention; Figure 3 is a flowchart of the GL registration stage in the lightweight group handover authentication method provided in an embodiment of the present invention; Figure 4 is a flowchart of the handover authentication stage in the lightweight group handover authentication method provided in an embodiment of the present invention; Figure 5 is a flowchart of the interaction between the device and the T-gNB in the lightweight group handover authentication method provided in an embodiment of the present invention; Figure 6 is a system architecture diagram of the lightweight group handover authentication method provided in an embodiment of the present invention; Figure 7 is a structural schematic diagram of the electronic device provided in an embodiment of the present invention. Detailed Implementation
[0025] To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to specific embodiments and accompanying drawings.
[0026] It should be noted that, unless otherwise defined, the technical or scientific terms used in the embodiments of this invention should have the ordinary meaning understood by those skilled in the art to which this invention pertains. The terms "comprising" or "including," or similar words used in the embodiments of this invention, mean that the element or object preceding the word encompasses the elements or objects listed following the word and their equivalents, without excluding other elements or objects.
[0027] The English abbreviations involved in this invention have the following meanings: 5G: 5th Generation Mobile Communication Technology, is a new generation of communication technology that supports scenarios such as ultra-dense networks and heterogeneous access.
[0028] UDN: Ultra-Dense Networking, is a network architecture that increases network capacity by reducing the coverage area of a single base station, resulting in an increased frequency of user equipment handover.
[0029] UE: User Equipment, refers to terminal equipment that accesses the 5G network, including group leader (GL) and general UE.
[0030] GL: Group Leader, selected from UEs with strong computing and storage capabilities within the group, is responsible for aggregating member responses, verifying response validity, and interacting with the network side.
[0031] gNB: Next Generation NodeB, a radio access network node in a 5G network, including the source base station (S-gNB) and the target base station (T-gNB).
[0032] S-gNB: Source gNB (source base station), the base station accessed by the UE before handover, responsible for forwarding authentication signaling between GL and AMF.
[0033] T-gNB: Target gNB (Target Base Station), the base station accessed by the UE after handover, responsible for deriving the new session key, generating the response value, and completing the final authentication.
[0034] AMF: Access and Mobility Management Function, a 5G core network element, serves as the core trust anchor point, responsible for UE authentication, key derivation, and handover process coordination.
[0035] 5GC: 5G Core Network, the core component of the 5G network, providing core functions such as authentication and session management.
[0036] AKA: Authentication and Key Agreement, a protocol used in 5G networks for identity authentication and key negotiation between the UE and the core network.
[0037] Xn interface: The direct interface between 5G base stations. Existing technologies have security vulnerabilities and are prone to desynchronization attacks.
[0038] KFS: Key Forward Security, a security attribute proposed in 5G standard documents that 5G handover authentication must meet. KFS means that "the disclosure of the communication key of the previous hop will not help an attacker to crack the communication key of the next hop".
[0039] vkd: Vertical Key Derivation, used in this invention to derive the communication key between the UE and the T-gNB, ensuring forward confidentiality of the key.
[0040] hkd: Horizontal Key Derivation, a current method of key derivation that carries the risk of forward confidentiality failure.
[0041] NCC: Next Hop Chaining Counter, a counter used for key derivation during the switching process, which is easily tampered with, leading to desynchronization attacks.
[0042] DoS: Denial of Service, is an attack method that causes group authentication to fail by sending invalid responses or other means.
[0043] MAC: Message Authentication Code, a verification value used to verify data integrity and identity legitimacy. In this invention, it is generated using the HMAC algorithm.
[0044] HMAC: Hash-Based Message Authentication Code, an algorithm used to generate MAC values to ensure data integrity and authentication.
[0045] KDF: Key Derivation Function, an algorithm used to derive new keys from initial key materials. In this invention, the HKDF algorithm is used.
[0046] HKDF: HMAC-based Key Derivation Function, a specific key derivation algorithm used to generate root keys, session keys, etc.
[0047] AES: Advanced Encryption Standard, a symmetric encryption algorithm used to encrypt and decrypt data such as identity authentication credentials.
[0048] senc: Symmetric Encryption, refers to the process of encrypting data using the AES algorithm.
[0049] sdec: Symmetric Decryption, refers to the process of decrypting data using the AES algorithm.
[0050] NH: Next Hop, an intermediate parameter in the key derivation process used to generate subsequent session keys.
[0051] sid: Session Identifier, a unique string generated by GL to identify a single group-switching authentication session.
[0052] RES: Response (Response Value), a parameter generated by the T-gNB for UE authentication.
[0053] ACK: Acknowledgment, an acknowledgment message generated after the UE completes T-gNB authentication.
[0054] SUPI: Subscription Permanent Identifier, a user's permanent subscription identifier used in identity authentication processes.
[0055] TEE: Trusted Execution Environment, a hardware-level security isolation environment that some existing technologies rely on to ensure authentication security.
[0056] TA: Trusted Authority, a trusted entity used in existing technologies to generate system parameters and keys.
[0057] eMBB: enhanced Mobile Broadband, one of the three major application scenarios of 5G, pursuing high bandwidth and high speed.
[0058] mMTC: Massive Machine-Type Communication, one of the three major application scenarios of 5G, supports the access of massive numbers of IoT devices.
[0059] uRLLC: Ultra-Reliable Low-Latency Communication, one of the three major application scenarios of 5G, requires high reliability and low latency.
[0060] AP: Access Point, an access device in a wireless access network. 5G networks support heterogeneous AP access.
[0061] With the rapid development of 5G communication technology, enhanced mobile broadband (eMBB), massive machine-type communications (mMTC), and ultra-reliable low-latency communications (uRLLC) are placing higher demands on network performance. To meet the needs of massive device access and high-frequency communication, ultra-dense network (UDN) technology is widely used in 5G and future network architectures. By reducing the coverage area of a single base station, it improves network capacity and communication speed, but it also leads to a significant increase in the frequency of user equipment (UE) handover between base stations.
[0062] 5G networks support heterogeneous access modes, allowing UEs to access the core network through various wireless access points such as cellular networks and WiFi, forming a complex heterogeneous network architecture. This characteristic presents a dual challenge to the design of handover authentication protocols: on the one hand, they need to adapt to the security requirements of diverse devices; on the other hand, existing handover protocols based on the Xn interface have significant security vulnerabilities. When the source base station (S-gNB) is infected, attackers can launch desynchronization attacks by tampering with the Next Hop Chaining Counter (NCC) value, or use the horizontal derived key (hkd) to invalidate the forward secrecy (KFS) of the communication key, seriously threatening network communication security.
[0063] To address the surge in core network signaling and computational overhead caused by simultaneous handover of numerous devices, existing technologies generally employ group authentication schemes. This involves grouping devices with consistent movement trajectories into groups, with the group leader (GL) aggregating member responses to achieve single-batch authentication of the group by the core network, thereby reducing network load. However, existing group handover authentication protocols still suffer from two major drawbacks: First, significant communication latency. During group handover, if some members have already entered the target base station (T-gNB) coverage area while the GL remains in the S-gNB coverage area, authentication cannot be initiated until the GL enters the T-gNB range, preventing earlier-arriving members from communicating in a timely manner. Second, vulnerability to DoS attacks. Attackers can send invalid responses during the GL aggregation phase, causing the aggregated responses of the entire group to fail AMF authentication, resulting in authentication failure.
[0064] To address these issues, related technologies have attempted to optimize performance through pre-switching mechanisms and aggregated signatures, but limitations remain. For example, some solutions rely on trusted relay hardware and trajectory prediction technology, making them only applicable to specific scenarios and lacking versatility; some solutions' batch verification mechanisms do not consider DoS attack protection, meaning that an invalid signature from a single malicious member can cause batch authentication to fail. Furthermore, existing solutions are mostly based on ideal assumptions about GL or base station security, failing to fully consider potential untrusted node scenarios in real-world networks, making it difficult to guarantee key consistency and communication confidentiality.
[0065] Therefore, in 5G and UDN network environments, there is an urgent need for a lightweight group handover authentication technology that balances low latency, high security, and versatility to address the problems of high handover latency, weak anti-attack capabilities, and limited applicability in existing solutions, and to meet the reliable communication requirements of large-scale device access scenarios. The network model of this invention involves three types of entities: UE, gNB, and AMF. UEs are logically divided into GLs and general UEs. All UEs in the network are divided into several groups, with one UE in each group selected as the GL, and the rest as general UEs. In this invention, it is assumed that a group consists of... The UE consists of 1 UE, denoted as UE , of which serial number 1 to It is a typical UE, serial number Other sub-entities in the 5G core network (5GC), such as AUSF and NSSF, are ignored in the model because these network elements generally do not participate in the handover authentication process. The following is a detailed description of an embodiment of the present invention.
[0066] As shown in Figure 1, this embodiment of the invention provides a lightweight group handover authentication method, including: S1, initialization phase, each user equipment (UE) and the 5G core network (5GC) complete authentication and negotiate a session key through the 5G-AKA protocol. The UE and the AMF respectively derive the root key, NextHop parameters, and session key based on the session key. The AMF securely distributes the session key to the source base station (S-gNB), and the UE and S-gNB establish communication based on the session key; S2, registration phase, based on the key foundation of the initialization phase, UEs to be joined to the group sequentially complete AMF registration and group leader (GL) registration. The AMF registration confirms the UE through bidirectional MAC verification. In the AMF identity verification process, the AMF generates an identity authentication token for the UE. The GL registration completes identity verification using the token submitted by the UE, and the UE and GL negotiate to generate a shared key. In the S3 handover authentication phase, the GL initiates a handover request based on the group association relationship established during the registration phase. The AMF coordinates with the target base station T-gNB to derive the key and response information required for handover using the key parameters derived during the initialization phase. A signaling channel between the GL and T-gNB is constructed through a message relay mechanism. Pre-aggregation verification is performed using the shared key negotiated during the registration phase. After filtering invalid responses, valid responses are aggregated to complete the final authentication between the UE and T-gNB and establish secure communication after handover.
[0067] In this embodiment, the initialization phase of step S1 specifically includes the following steps: S11: Each device 5GC authenticates and negotiates session keys via the 5G-AKA protocol. .
[0068] S12: Equipment The root key is derived from AMF. , Session key These parameters are used for subsequent switching authentication.
[0069] S13: AMF will transfer the session key Securely sent to gNB.
[0070] After the initialization phase is completed, the device Use a key between gNB and To conduct communication.
[0071] Referring to Figure 2, in the registration phase of step S2, devices other than GL sequentially register with AMF and GL of the target group, which are respectively referred to as the AMF registration process and the GL registration process. The specific steps are as follows.
[0072] S21: Equipment Generate a random number As a challenge, and using Generate a MAC value To ensure , and The integrity. Then, Will , , and Send to AMF.
[0073] S22: After receiving the parameters, AMF also uses... , , and Generate a MAC value By comparison and The validity of the parameters is confirmed by checking for consistency. Then, AMF generates a random number. To serve as a counterpart The challenge, and using the key Generate a MAC value To simultaneously serve as a challenge Response and guarantee The integrity of the system. Finally, AMF will... and Send to device .
[0074] S23: Equipment Also used , and Generate a MAC value By comparison and The consistency of parameters is used to verify their validity and to certify the AMF. Then the device... use and generate As a challenge to AMF The response.
[0075] S24: Generate in AMF following the same steps. And through comparison and Whether they are consistent is used to confirm the equipment. After verifying the identity, GL's communication key will be used. and root key A MAC value is derived from each other. . Will be used as equipment The certificate is used to prove identity to GL during the subsequent GL registration process. Then, AMF first uses the key. To encrypt generate and for Generate a MAC value To ensure The integrity of the system. Finally, AMF will... and Send together to the device .
[0076] S25: Equipment First use from Decryption obtained Then use , , and To generate MAC value By comparison and The validity of the parameters is confirmed by checking for consistency. If the verification passes, the data is saved. .
[0077] Referring to Figure 3, after the AMF registration phase, the device Obtain This is used to prove its identity to the target GL. The specific steps are as follows.
[0078] S26: Equipment Generate random numbers As a challenge, and using pre-stored... and ID Let's generate MAC values together. , used to ensure The integrity of the device. Then, the device will... , and Send to GL.
[0079] S27: GL also uses a communication key. and root key Derived from the HMAC algorithm Then use and Derived MAC value and through inspection and Whether they are consistent is used to verify the equipment. effectiveness and The validity of the check. If the check passes, GL stores... and use , and Generate MAC value As a response to the challenge The response.
[0080] S28: Upon receiving After that, the equipment Also use its own , and To generate the expected response. .if and If they are consistent, then the equipment The GL registration process is considered to have successfully concluded.
[0081] After successfully completing the GL registration phase, i.e., the device After successfully joining the group, GL and GL will generate the same key respectively. This key will be used for GL and [other authentication methods] during the authentication switch phase. Mutual authentication between them.
[0082] In this embodiment, during the authentication switching phase in step S3, the AMF, with the assistance of GL and S-gNB, authenticates a group of devices. Simultaneous authentication is performed. Once a device enters the coverage area of the T-gNB, the T-gNB is responsible for a final handshake with each device to ensure that each legitimate device has successfully associated with the T-gNB. Furthermore, this invention employs a message relay mechanism at this stage to reduce signaling latency between the GL and the T-gNB. The handover authentication phase process is shown in Figure 4, where dashed lines indicate messages that may be forwarded by devices already in the T-gNB area. The specific steps are as follows.
[0083] S31: GL first generates a random number. Used to uniquely identify the entire authentication session. Then, GL uses... and right and constant Encryption generation Finally, GL will and Send to S-gNB.
[0084] S32: S-gNB is used first. from Decrypt the parameters and Through inspection Is it related to common constants? To verify the same If the verification passes, S-gNB will... and Forwarded to AMF.
[0085] S33: AMF usage and Generate the expected MAC value Through inspection and To confirm whether they are consistent The validity of the validation. If the validation passes, AMF will derive a new one for each device in the group. and Send them together to T-gNB.
[0086] S34: T-gNB according to , and common constants For each device in the group Derive new session keys respectively and response and using all responses and To derive a MAC value Ensure the integrity and authenticity of these responses. When a device enters the T-gNB's range in the group, the T-gNB sends all generated response values and... .
[0087] S35: After receiving all the parameters, GL first... and the current To derive the latest NextHop (NH) value Then use the latest NH value and Derive the latest communication key Secondly, GL uses all received responses and Generate expected MAC value By comparison and The consistency of the received response value is used to check its validity. Again, GL uses common constants. and Generate the expected response value By comparison and The consistency of the T-gNB is used for authentication. If both checks pass, GL will... and Send to each device in the group separately .
[0088] S36: Each device Firstly, according to and the current To derive the latest NH value Then use the latest NH value and Derive the latest communication key Secondly, Use public constants and Generate the expected response value By comparison and The consistency of the T-gNB is used for certification. If the certification passes, Use respectively and common constants To generate a response to AMF. and use , and Generate MAC value Finally, the equipment Will and Send to GL.
[0089] S37: For each device GL based on the received , and To generate the expected MAC value By comparison and Whether they match confirms the received response. Is it effective? After collecting responses from all devices within the group, GL uses an XOR operation to aggregate all remaining responses. And forwarded it to T-gNB.
[0090] S38: T-gNB usage and common constants For each device in the group Generate responses respectively And also aggregate them using XOR. T-gNB has been verified. and Consistency is used to authenticate groups.
[0091] In one possible embodiment, after successfully completing the handover authentication phase, each device Both can use the newly generated session key Communication with the T-gNB. Referring to Figure 5, when GL is not the first device to enter the T-gNB coverage area, a message relay mechanism is used to facilitate communication between GL and the T-gNB. Assume the first device to enter the T-gNB's range is... The T-gNB first determines the corresponding GL based on the device's ID, and then decides what information to send to the device. The specific steps are as follows: a1): Equipment Firstly, according to and the current To derive the latest NH value and use Let's derive one MAC value Then and Send to T-gNB.
[0092] a2): T-gNB passes Find Then use and Generate the expected MAC value T-gNB has been verified. and Consistency to Perform authentication. If authentication is successful, then process all response parameters (i.e., all responses and...) and session identifier Send to device .
[0093] a3): Equipment use and To derive the latest communication key and use and common constants to generate in advance .if and If they are consistent, then the equipment It is believed that this message was sent by T-gNB.
[0094] After authentication, all subsequent signaling between GL and T-gNB will be handled by [the relevant authority / organization]. Forward it.
[0095] The application scenarios of this invention are as follows: Scenario 1: Industrial Internet of Things (IIoT) scenario: In industrial production environments, a large number of sensors, controllers, robots, and other devices need to work collaboratively in groups. These devices have relatively fixed movement trajectories but frequent switching, and extremely high requirements for communication latency and security. Delays in production command transmission may cause production line shutdowns, and attacks on equipment can lead to production safety risks. This invention reduces switching latency through a message relay mechanism and resists DoS attacks through pre-aggregation verification, ensuring that device groups can maintain efficient collaboration and secure communication even when switching between base stations, thus meeting the high reliability requirements of industrial scenarios.
[0096] Scenario 2: Intelligent Transportation Scenarios: Vehicle clusters on highways and urban roads need to access the network as groups, frequently switching between base stations along the route. This invention supports dynamic group management, allowing vehicles to flexibly join / leave groups. A message relay mechanism avoids communication interruptions caused by different base stations covering the first and last vehicles in a convoy, ensuring low-latency data transmission between vehicles and between vehicles and roadside units. Passenger terminals (mobile phones, tablets) and onboard equipment (monitoring, communication modules) in high-speed rail and subway carriages form temporary groups. The high-speed movement of the train causes rapid switching between dense base stations along the route. This invention does not rely on trajectory prediction or dedicated hardware, reduces core network overhead through lightweight certification, and ensures continuous transmission of video calls and onboard monitoring data during switching.
[0097] Scenario 3: Smart City IoT Scenario: In smart cities, IoT devices distributed across communities, parks, and municipal facilities need to be networked in groups. These devices are numerous, dispersed, frequently switch over, and are easily targeted by attacks. The pre-aggregation verification mechanism of this invention can filter invalid attack responses, while the N2 interface and vertical key derivation ensure communication security. Simultaneously, lightweight authentication reduces the operational pressure on the city's core network, adapting to the needs of large-scale device access in smart cities.
[0098] Scenario 4: Large Venues / Gatherings: In densely populated venues such as stadiums, concert halls, and exhibitions, numerous user terminals (mobile phones, wearable devices) form temporary groups due to crowd movement, frequently switching between densely deployed base stations within the venue. Existing solutions are prone to core network congestion and authentication delays due to simultaneous device switching, impacting user network experience. This invention reduces signaling overhead through group response aggregation and shortens authentication startup time through message relay mechanisms, ensuring smooth network operation even during switching of dense user groups and improving communication experience in large-scale event scenarios.
[0099] It should be noted that the method of this embodiment can be executed by a single device, such as a computer or server. The method of this embodiment can also be applied to a distributed scenario, where multiple devices cooperate to complete the task. In such a distributed scenario, one of these devices may execute only one or more steps of the method of this embodiment, and these multiple devices will interact with each other to complete the method for limiting the storage space of mobile micro-applications.
[0100] It should be noted that the above description describes some embodiments of the present invention. In some cases, the described actions or steps can be performed in a different order than that shown in the above embodiments and the desired result can still be achieved. Furthermore, the processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0101] Referring to Figure 6, based on the same inventive concept, this embodiment of the invention also provides a lightweight group handover authentication system. The lightweight group handover authentication method, employing the above embodiments or any possible implementation thereof, includes: an initialization unit 100, used for each user equipment (UE) to complete authentication and negotiate a session key with the 5G core network (5GC) via the 5G-AKA protocol; the UE and the AMF respectively derive a root key, NextHop parameters, and a session key based on the session key; the AMF securely distributes the session key to the source base station (S-gNB); and the UE and S-gNB establish communication based on the session key; and a registration unit 200, used for UEs to be added to the group to sequentially complete AMF registration and group leader (GL) registration based on the key foundation of the initialization unit. The AMF registration verifies the legitimacy of the UE and AMF identities through bidirectional MAC verification, and the AMF generates an identity authentication token for the UE. The GL registration completes identity verification through the token submitted by the UE, and the UE and GL negotiate to generate a shared key. The handover authentication unit 300 is used by the GL to initiate a handover request based on the group association relationship of the registration unit. The AMF coordinates the target base station T-gNB to derive the key and response information required for handover using the key parameters derived by the initialization unit. A signaling channel between the GL and T-gNB is constructed through a message relay mechanism. Pre-aggregation verification is performed with the shared key negotiated by the registration unit. After filtering invalid responses, valid responses are aggregated to complete the final authentication of the UE and T-gNB and establish secure communication after handover.
[0102] In this embodiment, the initialization unit 100 includes: an authentication and initial session key negotiation module 101, used for each UE to authenticate with the 5GC through the 5G-AKA protocol and negotiate an initial session key; a multi-dimensional key derivation module 102, used for the UE and AMF to derive a root key, key derivation intermediate parameters, and a base station communication key based on the initial session key through a key derivation algorithm, wherein the root key is used for UE and AMF authentication and key derivation, the key derivation intermediate parameters provide the basis for subsequent key generation, and the base station communication key is used for communication between the UE and the S-gNB; a base station communication key secure distribution module 103, used for the AMF to securely distribute the base station communication key to the S-gNB; and a UE and S-gNB encrypted communication establishment module 104, used for the UE and S-gNB to establish encrypted communication based on the base station communication key.
[0103] In this embodiment, the registration unit 200 includes: a UE authentication request generation module 201, used by the UE to generate a random challenge value, calculate a verification value using its own root key through a message authentication code algorithm, and then send the verification information to the AMF; an AMF two-way challenge and verification module 202, used by the AMF to calculate the verification value using the same parameters, generate a random challenge value after comparison, calculate the response verification value and feed it back to the UE; after the UE verifies the validity of the response verification value, calculates the challenge response value and sends it to the AMF, and after the AMF verifies the UE's identity, it confirms the UE's legitimacy; and an identity authentication credential derivation and encryption module 203, used by the AMF to derive identity authentication credentials based on the key parameters of GL, the identity authentication credentials serving as the UE's identity basis during the GL registration stage, encrypting the credentials through an encryption algorithm and calculating the complete credentials. The system includes: a UE authentication credential generation module 204, a UE credential decryption and storage module 205, a UE group access request generation module 205, a UE group access request generation module 206, a GL identity verification and response module 207, a shared key negotiation generation module 207, and a shared key negotiation generation module 208. The UE calculates the authentication credential by decrypting it, verifies its integrity, and stores it after verifying its integrity. The UE generates a random challenge value, calculates the verification value using the stored authentication credential and its own identity identifier, and sends the challenge value, identity identifier, and verification value to the GL. The GL derives the authentication credential based on its own key parameters, calculates the verification value, compares it with the received response value, confirms the validity of the UE's identity, and generates a response value. The UE calculates the expected response value and compares it with the received response value. If the UE and the GL agree, the registration is successful. The UE and the GL negotiate and generate a shared key through a key derivation algorithm for use in the response verification during the authentication phase.
[0104] In this embodiment, the handover authentication unit 300 includes: a relay UE identity authentication and key update module 301, used by the UE that first enters the T-gNB coverage area in the group as a relay device, derives the latest key intermediate parameters based on its own key parameters, calculates the verification value corresponding to the identity identifier, and sends it to the T-gNB; a T-gNB relay authorization and signaling delivery module 302, used by the T-gNB to query the corresponding key intermediate parameters through the identity identifier, verify the validity of the verification value, and send the response information, aggregated verification value, and session identifier of all UEs in the group to the relay UE; and a relay UE signaling verification and forwarding module 303, used by the relay UE to derive its own new communication key using the session identifier and the latest key intermediate parameters, verify the validity of its own response information, and forward all signaling to the GL; U The UE confirmation response and verification value generation module 304 is used to switch authentication phases. After each UE completes T-gNB identity authentication, it generates a confirmation response, calculates a verification value using the shared key negotiated with GL during the registration phase, the confirmation response, and the session identifier, and sends the confirmation response and verification value to GL. The GL single UE response verification and filtering module 305 is used by GL to calculate the expected verification value for each UE using the corresponding shared key, confirmation response, and session identifier. If the expected verification value matches the received verification value, the confirmation response is confirmed as a valid response; if they do not match, the invalid response is discarded and not included in the aggregation process. The GL valid response aggregation and submission module 306 is used by GL to aggregate all valid confirmation responses through XOR operation, generate an aggregated response, and forward it to T-gNB to complete group response aggregation.
[0105] The system described in the above embodiments is used to implement the corresponding lightweight group handover authentication method in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0106] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, the present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the lightweight group handover authentication method described in any of the above embodiments.
[0107] Figure 7 illustrates a more specific hardware structure of an electronic device provided in this embodiment. The device may include: a processor 410, a memory 420, an input / output interface 430, a communication interface 440, and a bus 450. The processor 410, memory 420, input / output interface 430, and communication interface 440 are interconnected internally via the bus 450.
[0108] The processor 410 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.
[0109] The memory 420 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 420 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program code is stored in the memory 420 and is called and executed by the processor 410.
[0110] Input / output interface 430 is used to connect input / output modules to realize information input and output. Input / output modules can be configured as components in the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Input devices may include keyboards, mice, touch screens, microphones, various sensors, etc., and output devices may include displays, speakers, vibrators, indicator lights, etc.
[0111] The communication interface 440 is used to connect a communication module (not shown in the figure) to enable communication between this device and other devices. The communication module can communicate via wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).
[0112] Bus 450 includes a pathway for transmitting information between various components of the device, such as processor 410, memory 420, input / output interface 430, and communication interface 440.
[0113] It should be noted that although the above-described device only shows the processor 410, memory 420, input / output interface 430, communication interface 440, and bus 450, in specific implementations, the device may also include other components necessary for normal operation. Furthermore, those skilled in the art will understand that the above-described device may only include the components necessary for implementing the embodiments of this specification, and not necessarily all the components shown in the figures.
[0114] The electronic devices described above are used to implement the corresponding lightweight group handover authentication method in any of the foregoing embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0115] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, the present invention also provides a non-transitory computer-readable storage medium storing computer instructions for causing the computer to execute the lightweight group handover authentication method as described in any of the above embodiments.
[0116] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transfer medium that can be used to store information accessible by a computing device.
[0117] The computer instructions stored in the storage medium of the above embodiments are used to cause the computer to execute the lightweight group handover authentication method as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0118] Those skilled in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of the invention is limited to these examples; within the framework of the invention, the technical features of the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations of the different aspects of the embodiments of the invention as described above, which are not provided in detail for the sake of brevity.
[0119] Additionally, to simplify the description and discussion, and to avoid obscuring the embodiments of the invention, the well-known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. Furthermore, the apparatus may be shown in block diagram form to avoid obscuring the embodiments of the invention, and this also takes into account the fact that the details of implementation of these block diagram apparatuses are highly dependent on the platform on which the embodiments of the invention will be implemented (i.e., these details should be fully understood by those skilled in the art). While specific details (e.g., circuits) have been set forth to describe exemplary embodiments of the invention, it will be apparent to those skilled in the art that the embodiments of the invention may be implemented without these specific details or with variations thereof. Therefore, these descriptions should be considered illustrative rather than restrictive.
[0120] Although the invention has been described in conjunction with specific embodiments thereof, many substitutions, modifications, and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., DRAM) may use the embodiments discussed.
[0121] The embodiments of this invention are intended to cover all such substitutions, modifications, and variations falling within the scope of the claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the embodiments of this invention should be included within the scope of protection of this invention.
Claims
1. A lightweight group handover authentication method, characterized in that, include: During the initialization phase, each User Equipment (UE) and the 5G Core Network (5GC) complete authentication and negotiate a session key through the 5G-AKA protocol. The UE and the AMF derive the root key, NextHop parameter, and session key respectively based on the session key. The AMF securely distributes the session key to the source base station (S-gNB), and the UE and S-gNB establish communication based on the session key. During the registration phase, based on the key foundation from the initialization phase, UEs to be added to the group sequentially complete AMF registration and group leader GL registration. The AMF registration verifies the legitimacy of the UE and AMF identities through bidirectional MAC verification, and the AMF generates an identity authentication token for the UE. The GL registration completes identity verification through the token submitted by the UE, and the UE and GL negotiate to generate a shared key; During the handover authentication phase, GL initiates a handover request based on the group association relationship in the registration phase. AMF coordinates with the target base station T-gNB to derive the key and response information required for handover using the key parameters derived in the initialization phase. A signaling channel between GL and T-gNB is constructed through a message relay mechanism. Pre-aggregation verification is performed using the shared key negotiated during the registration phase. Invalid responses are filtered out and valid responses are aggregated to complete the final authentication between the UE and the T-gNB and establish secure communication after handover.
2. The lightweight group handover authentication method according to claim 1, characterized in that, The specific implementation of the initialization phase includes: each UE and 5GC authenticate with each other through the 5G-AKA protocol and negotiate an initial session key; the UE and AMF respectively derive a root key, key derivation intermediate parameters, and a base station communication key based on the initial session key through a key derivation algorithm. The root key is used for UE and AMF authentication and key derivation, the key derivation intermediate parameters provide the basis for subsequent key generation, and the base station communication key is used for communication between the UE and S-gNB; the AMF securely distributes the base station communication key to the S-gNB, and the UE and S-gNB establish encrypted communication based on the base station communication key.
3. The lightweight group handover authentication method according to claim 1, characterized in that, The specific steps of AMF registration are as follows: The UE generates a random challenge value, calculates a verification value using its own root key through a message authentication code algorithm, and then sends the verification information to the AMF; the AMF calculates the verification value using the same parameters, generates a random challenge value after comparison, calculates the response verification value, and sends it back to the UE; after the UE verifies the validity of the response verification value, it calculates the challenge response value and sends it to the AMF; after the AMF verifies the UE's identity, it confirms the UE's legitimacy; the AMF derives an identity authentication credential based on the GL key parameters, and the identity authentication credential serves as the UE's identity basis during the GL registration stage. The credential is encrypted using an encryption algorithm, and an integrity verification value is calculated; the UE decrypts the identity authentication credential, verifies the integrity verification value, and stores the credential.
4. The lightweight group handover authentication method according to claim 1, characterized in that, The specific steps of GL registration are as follows: The UE generates a random challenge value, calculates a verification value using the stored identity authentication credential and its own identity identifier, and sends the challenge value, identity identifier, and verification value to the GL; The GL derives an identity authentication credential based on its own key parameters, calculates the verification value, and confirms the UE's identity is valid after comparison, and generates a response value; The UE calculates the expected response value and compares it with the received response value, and if they match, the registration is successful. The UE and the GL negotiate to generate a shared key through a key derivation algorithm, which is used for response verification during the switching authentication phase.
5. The lightweight group handover authentication method according to claim 1, characterized in that, The message relay mechanism is implemented as follows: The UE that first enters the T-gNB coverage area in the group acts as a relay device. It derives the latest key intermediate parameters based on its own key parameters, calculates the verification value corresponding to the identity identifier, and sends it to the T-gNB. The T-gNB queries the corresponding key intermediate parameters through the identity identifier, verifies the validity of the verification value, and sends the response information, aggregated verification value, and session identifier of all UEs in the group to the relay UE. The relay UE uses the session identifier and the latest key intermediate parameters to derive its own new communication key. After verifying the validity of its own response information, it forwards all signaling to the GL. Subsequent handover authentication signaling between the GL and the T-gNB is bidirectionally forwarded through this relay UE until the GL enters the T-gNB coverage area.
6. The lightweight group handover authentication method according to claim 1, characterized in that, The pre-aggregation verification mechanism is implemented as follows: During the handover authentication phase, after each UE completes T-gNB identity authentication, it generates a confirmation response, calculates a verification value using the shared key negotiated with GL during the registration phase, the confirmation response, and the session identifier, and sends the confirmation response and verification value to GL; For each UE, GL calculates the expected verification value using the corresponding shared key, confirmation response, and session identifier; If the expected verification value matches the received verification value, the confirmation response is confirmed as a valid response; If they do not match, the invalid response is discarded and not included in the aggregation process; GL aggregates all valid confirmation responses through XOR operation, generates an aggregated response, and forwards it to T-gNB to complete the group response aggregation.
7. A lightweight group handover authentication system, characterized in that, include: An initialization unit is used for each user equipment (UE) to complete authentication and negotiate a session key with the 5G core network 5GC through the 5G-AKA protocol. The UE and AMF respectively derive the root key, NextHop parameter and session key based on the session key. The AMF securely sends the session key to the source base station S-gNB. The UE and S-gNB establish communication based on the session key. The registration unit is used to complete AMF registration and group leader GL registration in sequence based on the key of the initialization unit. The AMF registration confirms the legitimacy of the UE and AMF identities through bidirectional MAC verification, and the AMF generates an identity authentication token for the UE. The GL registration process verifies identity using the token submitted by the UE, and the UE and GL negotiate to generate a shared key. A handover authentication unit is used by the GL to initiate a handover request based on the group association relationship of the registration unit. The AMF coordinates with the target base station T-gNB to derive the handover key and response information using the key parameters derived by the initialization unit. A signaling channel between the GL and T-gNB is constructed through a message relay mechanism. Pre-aggregation verification is performed using the shared key negotiated by the registration unit, filtering invalid responses and aggregating valid responses to complete the final authentication between the UE and T-gNB, establishing secure communication after the handover.
8. A lightweight group handover authentication system according to claim 7, characterized in that, The initialization unit includes: an authentication and initial session key negotiation module, used for each UE to authenticate with the 5GC and negotiate an initial session key via the 5G-AKA protocol; a multi-dimensional key derivation module, used for the UE and AMF to derive a root key, key derivation intermediate parameters, and a base station communication key based on the initial session key through a key derivation algorithm. The root key is used for UE and AMF authentication and key derivation, the key derivation intermediate parameters provide the basis for subsequent key generation, and the base station communication key is used for communication between the UE and the S-gNB; a base station communication key secure distribution module, used for the AMF to securely distribute the base station communication key to the S-gNB; and a UE and S-gNB encrypted communication establishment module, used for the UE and S-gNB to establish encrypted communication based on the base station communication key.
9. A lightweight group handover authentication system according to claim 7, characterized in that, The registration unit includes: a UE authentication request generation module, used by the UE to generate a random challenge value, calculate a verification value using its own root key through a message authentication code algorithm, and then send the verification information to the AMF; an AMF two-way challenge and verification module, used by the AMF to calculate the verification value using the same parameters, generate a random challenge value after comparison, calculate the response verification value and send it back to the UE; after the UE verifies the validity of the response verification value, it calculates the challenge response value and sends it to the AMF, and the AMF confirms the UE's legitimate identity after verification; and an identity authentication credential derivation and encryption module, used by the AMF to derive identity authentication credentials based on the GL key parameters, the identity authentication credentials serving as the UE's identity basis during the GL registration phase, encrypting the credentials through an encryption algorithm and calculating integrity verification. The system comprises the following modules: a UE credential decryption and storage module, used by the UE to decrypt the identity authentication credential, verify its integrity, and store it after confirming the credential's integrity; a UE group access request generation module, used by the UE to generate a random challenge value, calculate a verification value using the stored identity authentication credential and its own identity identifier, and send the challenge value, identity identifier, and verification value to the GL; a GL identity verification and response module, used by the GL to derive the identity authentication credential based on its own key parameters, calculate the verification value, and confirm the UE's identity is valid after comparison, and generate a response value; and a shared key negotiation generation module, used by the UE to calculate the expected response value and compare it with the received response value, if they match, the registration is successful, and the UE and GL negotiate to generate a shared key through a key derivation algorithm for use in the response verification during the switching authentication phase.
10. A lightweight group handover authentication system according to claim 7, characterized in that, The handover authentication unit includes: a relay UE identity authentication and key update module, used by the UE that first enters the T-gNB coverage area in the group as a relay device, derives the latest key intermediate parameters based on its own key parameters, calculates the verification value corresponding to the identity identifier, and sends it to the T-gNB; a T-gNB relay authorization and signaling delivery module, used by the T-gNB to query the corresponding key intermediate parameters through the identity identifier, verify the validity of the verification value, and send the response information, aggregated verification value, and session identifier of all UEs in the group to the relay UE; a relay UE signaling verification and forwarding module, used by the relay UE to derive its own new communication key using the session identifier and the latest key intermediate parameters, verify the validity of its own response information, and forward all signaling to the GL; and a UE confirmation response module. The following modules are used: The UE and GL Single UE Response Verification and Filtering Module: The GL generates a confirmation response after completing T-gNB authentication. It calculates the verification value using the shared key negotiated with the GL during registration, the confirmation response, and the session identifier, and sends the confirmation response and verification value to the GL. The GL Single UE Response Verification and Filtering Module: For each UE, the GL calculates the expected verification value using the corresponding shared key, confirmation response, and session identifier. If the expected verification value matches the received verification value, the confirmation response is confirmed as valid; otherwise, the invalid response is discarded and not included in the aggregation process. The GL Valid Response Aggregation and Submission Module: The GL aggregates all valid confirmation responses using an XOR operation, generates an aggregated response, and forwards it to the T-gNB, completing the group response aggregation.